cbcvebase.
CVE-2020-26147
published 2021-05-11

CVE-2020-26147: An issue was discovered in the Linux kernel 5.8.9. The WEP, WPA, WPA2, and WPA3 implementations reassemble fragments even though some of them were sent in…

PriorityP434medium5.4CVSS 3.1
AVAACHPRNUIRSUCLIHAN
EPSS
7.60%
93.9th percentile
An issue was discovered in the Linux kernel 5.8.9. The WEP, WPA, WPA2, and WPA3 implementations reassemble fragments even though some of them were sent in plaintext. This vulnerability can be abused to inject packets and/or exfiltrate selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used.

Affected

18 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 5.10.46-1 (bookworm)linux 5.10.46-1 (bookworm)
googleandroid
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 4.15.0-151.1574.15.0-151.157
linuxlinux_kernel>= 0 < 5.4.0-77.865.4.0-77.86
linuxlinux_kernel>= 0 < 4.4.0-222.2554.4.0-222.255
linuxlinux_kernel>= 0 < 4.4.0-219.2524.4.0-219.252
linuxlinux_kernel>= 4.14 < 4.14.2354.14.235
linuxlinux_kernel>= 4.19 < 4.19.1934.19.193
linuxlinux_kernel>= 4.4 < 4.4.2714.4.271
linuxlinux_kernel>= 4.9 < 4.9.2714.9.271
linuxlinux_kernel>= 5.10 < 5.10.425.10.42
linuxlinux_kernel>= 5.12 < 5.12.95.12.9
linuxlinux_kernel>= 5.4 < 5.4.1245.4.124

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N
nvdv2.03.2LOWAV:A/AC:H/Au:N/C:P/I:P/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_cisco6.5MEDIUM
vendor_debian5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.